NewsLayer.com
NewsLayer PulseLIVEBTC$77,219-0.37%ETH$2,526-1.56%SOL$102.06+0.13%XRP$1.37+0.02%DOGE$0.085+0.00%ADA$0.2074+0.18%Total Cap$2.63T-1.59%Layer Index44 Neutral

AI agents exploited PaperCut flaws to breach 395 organizations

A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the work on their own, according to GreyNoise.

helpnetsecurity.com

Publisher

Sep 11, 2026 at 10:05 AM UTC · Updated một ngày trước · 2 phút đọc

AI agents exploited PaperCut flaws to breach 395 organizations
Image via helpnetsecurity.com
Đang dịch…

A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the work on their own, according to GreyNoise.

The result was at least 440 compromised PaperCut instances across 395 identified organizations in 48 countries.

Attacker, believed to be Russian-speaking, first built a private lab environment with a vulnerable copy of PaperCut NG/MF and an Active Directory server to develop and test exploits for two vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078.

“As part of the adversary’s exploit development and testing, they built and attacked a lab environment that included the vulnerable PaperCut software and an Active Directory server. In parallel workflows, the adversary built target lists using an internet scanning service Netlas.io using an identified API key,” researchers explained.

The agents ran on OpenAI’s Codex harness paired with a DeepSeek model, along with publicly available offensive security tools.

Help Net Security reported that PaperCut Software confirmed exploitation of the two vulnerabilities in late August and released emergency patches, urging customers to restrict access to the Application Server from the public internet.